This version is no longer in force.
It took effect on 2026-09-03 and was superseded on 2026-09-08. It is kept here unchanged so that anyone who needs the version in force on a past date can cite it.
Read the current privacy policyVersion of 2026-09-03
Privacy policy
We collect what running the service requires and not much else: your account details, the audio you give us to process, and what you used. Analytics run on the marketing site only if you agree first, and nowhere near your audio; there is no advertising pixel and no cross-site tracking. Your audio is never training data. Deletion and export are self-serve.
Who holds your data
The company operating Euphona (SOGV2 Limited (CR No. 76825703)) is the controller of the personal data described here.
We have not yet appointed a representative in the European Union, or in the United Kingdom. A company outside those places that offers services to people inside them generally has to appoint one, and we are not going to argue ourselves into the narrow exemption for occasional low-risk processing — recordings carry people’s voices and we process them continuously. The appointment is outstanding, and it is named here rather than left for you to notice.
Data-protection questions go to privacy@euphonaai.com, and a person reads that address.
What we collect
- Account details — your email address, your name if you give one, and whichever sign-in method you chose. If you set a password, we hold it only as a salted hash from a deliberately slow function — a value that can be checked against the password you type but cannot be turned back into it. Nobody here can read your password, including us, and a copy of our database would not reveal it. If you sign in with Google instead, we hold the identifier Google returns and there is no password to store at all.
- Audio you upload, the analysis derived from it, and the results produced from it. See below — this is the part that matters most.
- Usage and metering — which jobs ran, how long the audio was, what they cost, and whether they succeeded. This is how a bill is calculated and how a support question is answered.
- Billing details — held by Stripe, our payment processor, not by us. We store an identifier, your plan and your invoice history. We never see your card number.
- Support correspondence — what you wrote to us and what we replied.
- Technical logs — request identifiers, timings, errors and coarse information about the client. Kept short, used to find out why something broke.
Two of the free tools never receive your audio. The loudness checker and the BPM & key finder run in your browser; the file is decoded and measured on your own device, and there is no endpoint on those pages to send it to. That is not a policy we could quietly change without you noticing — it is how the pages are built, and you can watch the network tab to confirm it.
The vocal remover is the exception, and it is labelled as one. It uploads the file to our servers, because the separation runs on the engine, and it holds the upload and the two parts made from it for at most twenty-four hours before deleting them automatically (see retention below). While we hold them they are your audio in every sense the section on your audio describes: private, unlistened-to by anyone here, never training data. If you sign up and move the result into your account, it becomes an ordinary file in your workspace and is kept as one.
What we do see is the request for the page itself, because that is an ordinary web request and it appears in the technical logs above like every other one — including your IP address. An IP address is personal data, so we would rather say this than let “the tools collect nothing” do work it cannot do. We use it for two things: finding out why something broke, and counting requests per address so that the tools can stay free without an account, which they only can while nobody automates them. The acceptable use policy says the same thing from the other side. It is not linked to an account, not used to build a profile, and it ages out with the rest of the logs.
Children
You need to be at least 16 to have an account. That is the age at which, across the places our users live, a person can agree to a service like this one for themselves rather than through a parent — we use a single number instead of checking your country, because a policy that gives you fewer rights depending on your address is the thing this document is trying not to be.
We do not knowingly collect data from anyone younger, and we do not profile age or infer it. If you are a parent or guardian and believe a child has made an account here, write to privacy@euphonaai.com and we will close it and delete what it holds. You do not need to prove anything first; we would rather act on a plausible message than make you produce documents about your own child.
The browser-based free tools are a deliberate exception, and only because they can be: they need no account, they collect no audio, and a fifteen-year-old measuring the loudness of their own mix in their own browser is not something we need to know about, let alone gate. The vocal remover asks no age either, but it does take an upload, which exists on our servers for up to twenty-four hours; a parent who would rather it did not can reach us the same way and we will delete it then rather than later.
Your audio, specifically
It is never used to train anything. Not our models, not anyone else's. If we ever want to, we will ask you separately and explicitly, you will be able to say no, and you will be able to change your mind later. That consent does not exist yet because the machinery for honouring it does not exist yet, and asking for permission we could not yet keep would be worse than not asking.
It is private by default. It is stored in a location specific to your workspace, reachable only through links that are signed and expire. There is no public URL for your audio and no way to guess one.
It is not read by people. Our staff have no standing ability to listen to it. Where a support case genuinely requires it, we ask you first, and any internal access is recorded in an audit log that cannot be edited afterwards.
It is decoded carefully. Malformed media files are one of the oldest ways to attack a system, so decoding happens in a sandbox with no network access and nothing to reach — which protects you as much as it protects us, because the thing being attacked would be the process holding everyone's audio.
Why we hold it
To run the service you asked for, to bill you correctly, to answer you when something goes wrong, to keep the platform secure and to meet legal obligations such as keeping tax records. Where the law requires a legal basis to be named: performing our contract with you for most of it, our legitimate interest in security and service quality for the logs, and consent for anything optional — of which there is currently nothing.
Analytics, cookies and browser storage
This site measures how it is used, and only if you agree first. Before you answer there is no measurement script on the page at all — not one loaded and held in a disabled state, which is the usual arrangement and a weaker one. If you decline, or never answer, nothing is fetched and no analytics cookie is written.
What runs once you accept is Google Analytics 4, on this marketing site only. It sets its own cookies to tell a returning visit from a new one, and reports which pages were read, where the visit came from, an approximate location derived from your IP address, and the device and browser. We send it no account identifier, no name and no email address. It never runs in the Studio, where your audio is — that is a different origin with a different answer, and consent given here is not carried there.
You can change your mind whenever you like. “Analytics choice” in the footer of every page reopens the question, and declining after having accepted switches the tag off in that browser. Your answer is kept in a cookie of ours, eu_consent, for a year; it holds one word and identifies nobody.
Google processes this data for us and also for its own purposes, and it may be handled in the United States under the EU–US Data Privacy Framework. This paragraph replaced one that promised no analytics of any kind — that promise also said it would change before a tag shipped rather than after, and this is that change, published the same day.
The pages you can read without an account set nothing until you ask them to. Arrive, read, use the free tools, leave again — nothing is stored on your device by this page, by the guides or by the tools. One thing changes that, and only if you do it yourself: choosing the light or the dark theme records that choice, so the site is still in that theme the next time you open it.
That choice used to be kept in browser storage, and is now a cookie. The reason is worth stating plainly, because the older version of this page said it was not one. Browser storage is walled off per address, so a choice made on this site could not be seen by the sign-in pages or by the Studio — people who had asked for light were being shown dark the moment they went to log in. A cookie is the only thing that crosses those addresses. Being a cookie, it does travel to us with every request your browser makes; nothing on our side reads it, and it changes what your browser paints and nothing else.
Signing in sets two more, and starting a Google sign-in briefly sets a third. All of them are ours — the one third-party exception on this service is the analytics cookies described above, which exist only if you said yes — and all of them exist only to do the thing you asked for: to remember a display choice you made, and to carry out signing in and staying signed in. That is why none of them needs a consent banner: not one measures you, follows you between sites, or reports anything about you to anyone.
- eu_theme — the word light or the word dark, and nothing else. It exists only once you have chosen a theme; until then there is no such cookie and the site follows whatever your device already prefers. Scripts on the page can read it, because reading it before the page is drawn is the whole point — a theme applied a moment late is a white flash on every click. It identifies nothing and permits nothing: someone who forged it would get a page in the other colour. It lasts a year, is not cleared by signing out, and clearing it puts you back to following your device.
- eu_session — a reference to your signed-in session. It is a random value that means nothing on its own; the session it points to lives on our servers, which is what lets you sign out of every device and have that take effect. Marked HttpOnly and Secure, so no script on the page can read it and it never travels unencrypted. It expires after 30 days without use — using Euphona pushes that date back, so an account in regular use stays signed in rather than being turned out on a schedule — and after 400 days from the day you signed in whatever happens, which is the one date using Euphona does not move. Signing out ends it immediately, everywhere it counts.
- eu_session_hint — the single character 1, and nothing else. It records that somebody is signed in on this browser, so our public pages can offer you the Studio instead of asking you to log in again. Unlike the cookie above, scripts on the page can read it, which is why it holds no name, no email address, no account reference and no session value: reading it tells you only what the page you are looking at already shows. It cannot be used to sign in, prove anything, or reach anything. It is written and deleted at exactly the same two moments as the cookie above, and lasts exactly as long. If a session lapses through disuse the hint can outlast it, and all that happens is that a public page offers you the Studio and the Studio asks you to sign in — which is what it would have done anyway.
- eu_oauth_flow — set only while you are signing in with Google, and only on the sign-in site. It holds the one-time values that tie the trip to Google back to the browser that started it, which is what stops somebody walking you into an account that is not yours. It lasts two minutes and is deleted the moment you arrive back, whether the sign-in worked or not.
All four are first-party and set by us. None holds your name, your email address or anything about what you have uploaded — the session cookie is a random reference and nothing more. Blocking them costs you two things and nothing else: you cannot stay signed in, and a theme you choose will not survive the tab. Everything readable without an account works with cookies blocked entirely. Signing out clears both session cookies and ends the session on our side, so a copy of either is no longer any use to anyone; the theme is a preference rather than part of your session, so signing out leaves it alone.
If we ever set anything that is not strictly necessary, the consent mechanism ships in the same release rather than afterwards — and a refusal will be as easy as an acceptance.
Who else touches it
We use a small number of processors and each one exists for a stated reason: an email provider for service messages, a payment processor for billing and tax, and infrastructure for hosting, storage and backups. Each is bound to process data only on our instructions. Sign-in is not among them — accounts, passwords and sessions run on our own machines, so there is no third party standing between you and your account.
We do not sell personal data, we do not share it for advertising, and we do not hand it to data brokers. If we are ever legally compelled to disclose something, we will tell you unless we are prohibited from doing so.
No third party holds your audio. It sits on servers we administer, with storage we operate. The processors below hold identity, payment and email data:
- Resend (United States) — transactional email: address confirmation, password resets and security notices. Receives your email address and the contents of those messages, and nothing else.
- Google Analytics (United States and Ireland) — how the marketing site is used, and only for visitors who agreed to it. Receives page addresses, referrers, an approximate location from your IP address and your device type; never your audio, your account or your email address, and nothing at all from the Studio.
Sign-in is not delegated to anyone. Accounts, passwords and sessions run on our own machines: passwords are stored only as salted hashes from a deliberately slow function, never in a form that can be read back, and sessions are records we can revoke. If you sign in with Google, Google confirms who you are and we store the identifier they return — they are not told what you do here, and we never receive your Google password.
Stripe (United States and Ireland) handles payments. It receives your email address, your billing address, your card details and what you bought; we receive an identifier, your plan and your invoice history, and never your card number. It was named here before paid plans opened and before any charge was taken, which is the point — for everyone who pays, this notice came first.
For any processor we add after you become a customer, the data processing agreement promises thirty days’ notice before it touches anything of yours. It is a period you can object during, not a formality: write to privacy@euphonaai.com and if we cannot accommodate you, you can leave and we refund what you have not used. Each processor is engaged under terms no weaker than these.
What our own staff can see
Enough to help you and no more. Support tooling shows job records, error traces and account state — not the contents of your audio. Reading a customer record is itself recorded, in a separate append-only store, so the question “who looked at my account” has an answer that does not depend on anyone's memory or honesty.
How long we keep it
- Audio and results — until you delete them. Deleting is immediate in the service.
- Backups — deleted material can survive in encrypted backups for up to 14 days, after which the backup holding it is overwritten. Restoring a backup never resurrects something you deleted into your live account.
- Free tool uploads — the browser-based tools upload nothing. The vocal remover’s upload, and the two parts made from it, are purged within twenty-four hours, automatically, unless you sign up and move the result into your account — from then on it is kept like any other file in a workspace.
- Account and billing records — kept while your account is open, and afterwards only as long as tax and accounting law requires.
- Technical logs — a short rolling window, then gone.
- Dormant free workspaces — after ninety days of inactivity, stored source files may be reclaimed following three emails over a thirty-day period. Paid workspaces are never reclaimed this way.
Your rights, and how to use them
Depending on where you live you have rights to access, correct, delete, export, restrict or object to our processing of your personal data, and to complain to your data-protection authority. We apply all of them to everyone rather than checking your address first — the alternative is a worse product for people whose legislature has been slower, and we would rather not build the check.
Deletion and export are self-serve in your account, which is deliberate: a right you have to write an email to exercise is a right with friction on it, and friction is how these rights are usually defeated in practice.
If you are in the United States, the state laws that now cover most of the country add a right to know what we collect and why, to delete it, to correct it, to take a copy, and to opt out of its sale or of targeted advertising. There is nothing to opt out of here — we sell nothing, share nothing for advertising, and run no targeted advertising — but the right exists regardless of whether we exercise the practice, so it is stated rather than assumed away. We also honour the Global Privacy Control browser signal, and publish that as a machine-readable file so the claim is checkable without taking our word for it.
If we refuse a request, you can appeal it. Reply to our refusal, or write to the address below with “appeal” in the subject, and a different person reviews it. You will get an answer within sixty days with the reasoning, and if we still say no, we will tell you how to complain to your state attorney general. Several state laws require this; we would rather describe it as a route you can actually walk than as a clause you have to find.
For anything the self-serve path does not cover, write to privacy@euphonaai.com. We will verify who you are before acting — impersonating you is otherwise a way to have your work deleted — and we log each request and its outcome.
Where it is processed
Your audio is processed and stored on our own servers in the European Economic Area. Where a processor named above operates elsewhere — email, payments, analytics — transfers to it rely on the safeguards the law provides, such as the European Commission’s standard contractual clauses or an adequacy framework, and the countries involved are stated beside each processor.
How it is protected
Encryption in transit and at rest; signed and expiring access to every audio object; per-workspace storage separation; sandboxed decoding of untrusted media; audited internal access; encrypted backups on a fixed, bounded cycle.
The security page describes all of this in more detail. Read it here. If you find a problem, tell us at security@euphonaai.com.
Changes
If this policy changes materially we will tell you before it takes effect, and the date at the top always reflects the current version. A change that would newly involve your audio in anything is not something we would do by updating a policy page.